Strategic Export Controls: Airbus Record Settlement
Strategic Export Controls: Airbus’s Record £6.4M HMRC Settlement Explained.
What the largest strategic export settlement in HMRC history teaches every UK exporter about OGEL compliance
In July 2026, Airbus Operations Limited (AOL) paid a compound settlement of £6,409,388 to HM Revenue and Customs (HMRC) after admitting multiple breaches of Strategic Export Controls. It is the largest compound settlement HMRC has reached for strategic export offences, and the Export Control Joint Unit has published the details on GOV.UK.
The detail that should concern every UK exporter is what the breaches were. Airbus was not caught shipping weapons abroad without a licence. The settlement arose from repeated failures to keep precise records and registers of controlled technology transfers under the conditions of its Open General Export Licences. A business with a dedicated compliance function reached a record settlement, in substance, over documentation.
That is the lesson for the rest of the market. Strategic Export Controls in the UK are not only about whether you hold the right licence. They are about whether you can prove, on the correct records, that you used it properly. This article explains what the regime requires, what the Airbus case tells us, where export control violations most often arise, and how to build a compliance framework that would withstand HMRC scrutiny.
What are Strategic Export Controls and why do they matter?
Strategic Export Controls regulate the export, transfer, and supply of goods, software, and technology that have military, dual-use, or other strategic significance. The purpose is national security: to make sure that sensitive items, and the technology behind them, do not reach destinations or end-users where they could threaten the UK or its allies, or contribute to weapons programmes.
In Great Britain, the regime rests on the Export Control Act 2002 and the Export Control Order 2008, which set out both the controls and the offences for breaching them. Criminal enforcement is reinforced by the Customs and Excise Management Act 1979. Licensing is administered by the Export Control Joint Unit (ECJU), part of the Department for Business and Trade, while HMRC investigates and enforces suspected breaches, supported by Border Force at the frontier.
The controls reach a wide range of items: military goods on the UK Military List, dual-use items that have both civil and military applications, and the intangible transfer of controlled technology, including by email, remote access or the movement of staff. Each category carries its own licensing requirements. The regime is more complex still for firms operating across multiple markets or in politically sensitive regions, where a single shipment may engage UK controls, foreign controls and sanctions at the same time.
Understanding Open General Export Licences (OGELs)
Much of the UK export licensing regime runs on Open General Export Licences. An OGEL is a pre-published licence that permits the export of specified goods to specified destinations without applying for an individual licence, provided the exporter registers to use it and meets its conditions. OGELs reduce the administrative burden for lower-risk trade, but they shift responsibility onto the exporter to self-manage compliance.
It helps to distinguish the three principal licence types:
- Open General Export Licence (OGEL): a pre-published licence that any eligible exporter may use, once registered, if it meets the stated conditions. It covers defined goods and destinations.
- Open Individual Export Licence (OIEL): a bespoke licence issued to a named exporter, covering specified goods to specified destinations and consignees, usually valid for a set period and for multiple shipments.
- Standard Individual Export Licence (SIEL): a specific licence for a named exporter to send specified goods to a named consignee, typically for a set quantity or value and a limited period.
The critical point, and the one the Airbus case illustrates, is that OGEL compliance is not passive. Using an OGEL commits a business to a set of ongoing obligations, including keeping accurate records, maintaining registers of transfers, and observing every condition attached to the licence. A failure to meet those conditions is an offence in itself, regardless of whether the underlying export would otherwise have been permitted.
Case study: the Airbus Operations Limited settlement
According to the Notice to Exporters published by the ECJU, over a sustained period before November 2022 Airbus Operations Limited breached the Export Control Order 2008 as follows:
- Article 29(2)(a-g), on multiple occasions, by failing to keep accurate records of transfers of controlled technology as required by the conditions of three of its OGELs;
- Article 29(3), on multiple occasions, by failing to keep registers in relation to those OGELs;
- Article 29(2)(i), on multiple occasions, by failing to keep accurate records contrary to the conditions of one of its OGELs; and
- the conditions of a Standard Individual Export Licence (SIEL), on one occasion.
Those are offences contrary to Articles 38(1)(a) and (b) of the Export Control Order 2008.
The case came to HMRC’s attention through Airbus’s own voluntary disclosure. HMRC has confirmed that the company fully cooperated with the investigation and implemented remediation measures. Edwige Hill, a Deputy Director in HMRC’s Fraud Investigation Service, said the UK operates a strict licensing regime to keep military equipment out of the wrong hands, and that HMRC will use its powers to enforce controls on military goods in support of national security.
Two features of the case deserve emphasis. First, the liability flowed from record-keeping failures, not from unlicensed exports. Second, the outcome was a settlement rather than a prosecution precisely because Airbus disclosed the breaches and cooperated. Both points are instructive for any business relying on OGELs.
Common export control violations to watch for
The Airbus settlement sits within a wider pattern of export control violations that HMRC encounters. The most frequent include:
- unlicensed exports of military-listed goods or controlled dual-use items;
- failure to keep the records and registers required by OGEL conditions;
- non-compliance with the specific conditions attached to a SIEL or OIEL;
- inadequate control over intangible technology transfers and software exports; and
- export of items such as encrypted or cryptographic devices without the correct authorisation.
Two points of law are worth stating clearly, because they are commonly misunderstood. The basic offence of exporting a controlled item without a licence does not require HMRC to prove that the exporter knew a licence was needed, so a business can face liability even where the failure was inadvertent. End-use, or “catch-all”, controls work differently: they can require a licence for items that are not on any control list, but generally only where the exporter knows, suspects or is informed by the ECJU that the goods are intended for a relevant military or weapons-related end-use. The obligation there is to carry out proper due diligence on how goods may be used, and to act on what that diligence reveals.
Record maintenance requirements and documentation standards
Because so much export control liability turns on records, it is worth being precise about what compliant record-keeping requires. Under the Export Control Order 2008, and under the specific conditions of the OGELs and SIELs a business uses, exporters must keep accurate records of their controlled exports and transfers, maintain registers where required, and retain that documentation so that it is available for inspection during an ECJU compliance visit or an HMRC investigation. Records must generally be kept for a period of years, with the precise retention period set out in the licence conditions themselves.
In practice, this means being able to show what was exported or transferred, when, to whom, under which licence, and against which control list entry, and being able to produce the register on request. The Airbus breaches under Article 29 were, at their core, failures of exactly this kind. Sensible measures include a central register of licence usage, periodic internal audits of that register against actual shipments and technology transfers, clear ownership of the record-keeping function, and a document retention policy that meets or exceeds the periods stated in each licence.
The voluntary disclosure process
HMRC operates a voluntary disclosure process for unlicensed exports of controlled goods, as well as electronic transfers of controlled software and technology. Where a business identifies a breach, disclosing it proactively is almost always the right course. Outcomes range from educational visits and written warnings, through to compound settlements, and referral to prosecutors in the most serious cases.
A compound settlement is a financial payment that HMRC may offer to settle alleged strategic export offences out of court, under the Customs and Excise Management Act 1979 and the Export Control Order 2008. HMRC will only offer one where it considers there is sufficient evidence to prosecute. When deciding whether a settlement is appropriate, and at what level, HMRC weighs factors including the seriousness of the offence, whether there was any intent, the level of cooperation, the business’s compliance history, and the value of the goods, software or technology involved.
There is also a reputational dimension that has recently sharpened. HMRC has begun publicly naming companies that accept compound settlements. Petrofac Facilities Management Limited was the first company to be named, and Airbus Operations Limited is the second. HMRC says the change brings it into line with other UK law enforcement bodies and improves transparency. For exporters, this means a settlement is no longer necessarily a private matter, which raises the stakes of getting compliance right. Because the framing and timing of a disclosure can materially affect the outcome, specialist legal advice should be taken before any disclosure is made.
Working out which controls apply to your business
The starting point is classification: assessing each product, software item or technology against the UK Strategic Export Control Lists, which bring together the UK Military List and the dual-use controls. Classification is the exporter’s responsibility, and it is not always straightforward. Dual-use items, by definition, have both civil and military applications, and marginal cases turn on technical detail. Where an item is not listed, the end-use controls may still apply if there is a relevant military or weapons-related end-use.
Businesses trading internationally should also look beyond the UK regime. As we have explained in our review of the Bosch penalty, US export controls under the Export Administration Regulations (EAR) can attach to items rather than to borders, so foreign-made goods can be caught by the de minimis rules or the Foreign Direct Product Rule even where a transaction has no obvious US connection. US sanctions administered by OFAC can likewise reach non-US parties in some circumstances. Where classification or foreign exposure is unclear, exporters can seek a rating from the ECJU or take specialist legal advice.
Working with HMRC and the ECJU: audits and disputes
A business relying on OGELs should expect that the ECJU may carry out a compliance visit, and that HMRC may investigate where it suspects a breach. Preparation is what separates a manageable audit from a difficult one: organised records, trained staff, and clear internal procedures in place before any contact with regulators.
Disputes do arise, and not every regulator’s view is correct. Classification is a technical question, and an incorrect classification can be challenged. In our experience, robust and well-evidenced challenges to classification can lead to criminal proceedings being discontinued, and swift judicial recourse can be critical in securing the release of goods detained at the border. Early advice is often what makes the difference.
Building a strong export control compliance structure
The core lesson of the Airbus case is that compliance failures, and record-keeping failures in particular, carry serious financial and reputational consequences regardless of a company’s size or sophistication. An effective compliance system rests on a small number of pillars: correct classification of goods, software and technology; rigorous documentation and register-keeping under every licence used; regular internal audits; persistent staff training; and a clear, tested procedure for voluntary disclosure if something goes wrong.
If your business relies on OGELs, the most useful question to ask now is a simple one: if the ECJU asked to see your registers tomorrow, would they stand up? For many businesses, the honest answer is uncertain, and that is precisely the exposure the Airbus settlement illustrates.
Frequently asked questions
How do you apply for an export licence in the UK?
You begin by classifying your goods, software or technology against the UK Strategic Export Control Lists to establish whether a licence is required and, if so, which type. You then register with, and apply through, the Export Control Joint Unit’s online export licensing service, choosing the appropriate licence: an Open General Export Licence for lower-risk, pre-approved trade, or an Open Individual or Standard Individual Export Licence for activity that needs a bespoke authorisation. You will generally need a compliant licencing track record before applying for an Open Individual Export Licence, and you will also need to produce a written business case. Where classification is uncertain, you can request a rating from the ECJU or take specialist advice before applying.
What are OGEL compliance requirements?
Registering to use an Open General Export Licence commits a business to ongoing obligations rather than a one-off approval. In broad terms, the OGEL compliance requirements are: to trade only in the goods and to the destinations the licence covers; to meet every condition attached to the specific licence; to keep accurate records of the exports and transfers made under it; to maintain the registers the licence and the Export Control Order 2008 require; and to retain that documentation so it is available for an ECJU compliance visit. The Airbus settlement turned on failures in exactly these record and register requirements.
What happens if you breach export control laws in the UK?
Breaching UK export controls is a criminal offence under the Export Control Order 2008 and the Customs and Excise Management Act 1979. For offences connected with military and dual-use export controls, the maximum sentence on conviction on indictment is 10 years’ imprisonment, an unlimited fine, or both. In practice, HMRC frequently resolves breaches by compound settlement, a financial payment instead of prosecution, and it can also seize goods and revoke licences. Companies that accept a compound settlement may now be named publicly by HMRC, as both Petrofac and Airbus have been. Where a breach comes to light, a prompt voluntary disclosure, taken with specialist advice, is usually the best way to limit the consequences.
How AM Skinner Solicitors can help
If your business exports goods, software or technology, relies on Open General Export Licences, or is considering a voluntary disclosure to HMRC, we can help you assess your exposure and put it right. Our work covers classification, OGEL and SIEL compliance and record-keeping, voluntary disclosures and compound settlements, and the handling of ECJU compliance visits and HMRC investigations, including challenges to classification and the release of detained goods.
For a free initial consultation with an international trade law specialist, contact AM Skinner Solicitors. You can also read more about our Export Controls and Sanctions and Embargoes services.
This article is for general information only and does not constitute legal advice. Specific situations should be discussed with a qualified adviser.